Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e8d5a7d75b24054…

MALICIOUS

PDF

17.7 KB Created: 2019-05-02 18:30:02 +01:00 Authoring application: mPDF 5.7
MD5: 93d4f8fd567029041791a82595dab505 SHA-1: 7f968f32b9d589b1c982d0969e9c3246ada897ba SHA-256: 3e8d5a7d75b24054f8ef171e705bf37dae10cfb93cc648184a46a749f0417404
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or a method to distribute malicious content. The ClamAV detection as Pdf.Dropper.Agent-7198916-0 further confirms its malicious nature. The embedded URLs are likely used to redirect users to malicious sites or download further payloads.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7198916-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7198916-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093098099093/Buddha-Vol-4-The-Forest-of-Uruvela-Buddha-4-by-Osamu-Tezuka.pdf
    • http://loaminoo.linkpc.net/2095099094099095/Vision-of-Secrets-The-Vision-Series-Prequel-by-Vincent-Morrone.pdf
    • http://loaminoo.linkpc.net/9095095097097095/Focus-by-Sallie-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095097097094/Evan-s-Voice-by-Sallie-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095097093092/The-Black-Game---Teil-2-by-Karola-L-wenstein.pdf
    • http://loaminoo.linkpc.net/9095095097093094/Lowenstein-King-of-the-Forests-by-Jane-Roberts.pdf
    • http://loaminoo.linkpc.net/1090097091098099097/First-Love---Ein-verr-ckter-Sommer-by-Karola-L-wenstein.pdf
    • http://loaminoo.linkpc.net/9095095096097095/Lowenstein-Acts-of-Courage-and-Belief-by-Gregory-Stone.pdf
    • http://loaminoo.linkpc.net/1090092099099092096/Dark-Revenge---Brennende-Leidenschaft-by-Karola-L-wenstein.pdf
    • http://loaminoo.linkpc.net/9095095097098098/All-About-Sign-Language-Talking-With-Your-Hands-by-Felicia-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095095092092/Origins-of-the-Crash-The-Great-Bubble-and-Its-Undoing-by-Roger-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095096096098/Buddhist-Inspirations-Essential-Philosophy-Truth-and-Enlightenment-by-Tom-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095096097092/Voices-of-Protest-Documents-of-Courage-and-Dissent-by-Frank-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095096097090/Haiku-Inspirations-Poems-and-Meditations-on-Nature-and-Beauty-by-Tom-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095096096099/Creative-Interventions-for-Troubled-Children-and-Youth-by-Liana-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095096097093/The-Investor-s-Dilemma-How-Mutual-Funds-Are-Betraying-Your-Trust-and-What-to-Do-about-It-by-Louis-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095097093090/Dreaming-of-Cinema-Spectatorship-Surrealism-and-the-Age-of-Digital-Media-by-Adam-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095097092096/Weevils-In-The-Flour-An-Oral-Record-Of-The-1930-s-Depression-In-Australia-by-Wendy-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095095091097/Kiki-Lowenstein-Short-Story-Anthology-Volume-1-by-Joanna-Campbell-Slan.pdf
    • http://loaminoo.linkpc.net/4093097093095/When-Genius-Failed-The-Rise-and-Fall-of-Long-Term-Capital-Management-by-Roger-Lowenstein.pdf
    • http://loaminoo.linkpc.net/9095095097098098/All-About-Sign-Language-Talking-With-Your-